Aquaverde's vulnerability footprint is narrowly scoped to its Aquarius CMS product, with the recurring signal centered on information-disclosure risks stemming from sensitive-data handling, including credential leakage through log files and insufficiently protected credential storage. Live severity, exploitation activity, and exposure details are shown in the statistics alongside this summary.
The number and severity of CVEs published that impact products developed by Aquaverde over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-1010308CRITICAL Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive info | Jul 15, 2019 | 9.8 | 28 | NO | NO |
CVE-2019-9724HIGH aquaverde Aquarius CMS through 4.3.5 allows Information Exposure through Log Files because of an error in the Log-File writer component. | Apr 24, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-9734HIGH Aquarius CMS through 4.3.5 writes POST and GET parameters (including passwords) to a log file due to an overwriting of configuration parameters under certain circumstances. | Apr 24, 2019 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aquaverde.
Media articles that mention a CVE ID that affects a product developed by Aquaverde — matched by CVE ID, not by vendor name.